Guide
How to build and run a WordPress site with an AI agent
Install wordpress-agent-skills to build: it is the WordPress project’s own set, and it exists because agents reliably generate pre-Gutenberg patterns, skip block deprecations and miss plugin security conventions. Install hostinger-api-mcp-skills to run what you built: core and plugin updates ordered safely, known vulnerabilities reported before anything changes, and an account-wide audit of which installs are broken. The split is not a gap in the ecosystem — building WordPress and operating WordPress are different jobs with different failure modes, and the two sets are published by the two parties who own them.
Updated September 30, 2026 · first published September 30, 2026
At a glance
Side by side
| wordpress-agent-skills | hostinger-api-mcp-skills | |
|---|---|---|
| Publisher | The WordPress project | Hostinger |
| Licence | GPL-2.0-or-later | MIT |
| Job | Write WordPress correctly | Install, migrate, patch and audit |
| Covers | Blocks, block themes, plugins, REST, Interactivity and Abilities APIs, WP-CLI, performance, PHPStan, Playground | WordPress installs, imports, core and plugin updates, vulnerability reporting, cache, wp-admin login links |
| Runs against | Your codebase | Your Hostinger account |
| Scope limit | Teaches; does not host or update a live site | Hostinger-hosted sites only |
Step by step
How to do it
- 1
Install the WordPress set for the build
npx skills add WordPress/agent-skills --skill wp-plugin-development --yes, swapping the skill for wp-block-development, wp-block-themes or wp-rest-api as the work demands. wordpress-router picks the right one for a repo if you would rather not choose.
- 2
Let it correct the patterns an agent gets wrong
The set exists for specific, repeated failures: blocks written without deprecations, which produce "Invalid block" errors for every existing post; themes written pre-block-theme; plugin code that skips the settings API and the security conventions around it.
- 3
Stand the site up on a host
Hostinger’s hosting skill creates the website and installs WordPress; migrate-to-hosting imports an existing one from an archive and a database dump. This is where the WordPress set stops and a host’s begins.
- 4
Check before you update, not after
maintain-wordpress reads core, plugin and theme versions with their known vulnerabilities and reports what needs doing — including which vulnerable plugins have no fix and should be uninstalled — before changing anything.
- 5
Update one site at a time and prove each still loads
That is the order the skill enforces, and it is the right one: updates are queued jobs, so a success response means queued rather than done. Poll until the change shows, confirm the site still loads, then move to the next.
Why WordPress published its own skills
The repository says it plainly: AI assistants generate outdated WordPress patterns, miss security considerations in plugin development, and skip block deprecations in a way that produces "Invalid block" errors. Those are not general coding mistakes, they are WordPress-specific ones that a model trained on a decade of pre-Gutenberg tutorials makes by default.
It is worth knowing how the set was built, because the project discloses it rather than hiding it: the skills were generated with a model from the official Gutenberg and WordPress documentation, then reviewed and edited by WordPress contributors, and the repository links its own AI authorship note. That is a more honest provenance statement than most first-party skill sets make, and it is the reason to treat this as v1 rather than gospel.
The operating half is thinner, and only one publisher covers it
Building WordPress with an agent now has a first-party answer. Running one does not, beyond a single host: the maintenance, vulnerability and audit skills in this catalogue are Hostinger’s, and they reach Hostinger-hosted sites only. If your site is elsewhere, the update path is still wp-admin or WP-CLI by hand.
That is a real gap rather than a ranking. WordPress runs a large share of the web on hosts that have published nothing, and an agent cannot patch what it cannot reach. When another host ships an equivalent set it will be catalogued here and this paragraph will change.
FAQ
Common questions
Which agent Skill is best for WordPress?
For writing WordPress — blocks, themes, plugins, the modern APIs — the WordPress project’s own wordpress-agent-skills, with no close second: it is first-party, 18 skills deep, and the most-starred set in this area. For running a live site, Hostinger’s maintain-wordpress, with the caveat that it only reaches sites hosted there.
Do I need both?
Only if you do both jobs. A plugin or theme developer needs the WordPress set and nothing else. Someone maintaining client sites on Hostinger needs the operating set and may never touch the build one. They do not overlap, so installing both is not redundant.
Can an agent update WordPress plugins safely?
With maintain-wordpress the order is check, report, get approval, then update one site at a time confirming each still loads. The risk it does not remove is the update itself breaking a site — so the value is that it tells you which plugins carry known vulnerabilities and which have no fix at all, which is the decision, rather than clicking update on everything.
Were these skills written by AI?
The WordPress set was, and the project says so on the front page: generated from the official documentation with a model, then reviewed and edited by contributors, with a linked authorship disclosure. It is labelled v1 by its own authors. We catalogue it on provenance and quality, and the disclosure is a point in its favour rather than against it.
Related
Keep reading
- Migrate a website to a new host →
Moving an existing WordPress site without downtime.
- Build, host and launch a website →
The four-step chain, for a site that is not WordPress.
- Top Frontend & UI Design Skills →
Where the WordPress build set is ranked.
- Top web hosting & deploy Skills →
Where the operating set is ranked.